Skip to content

FAQ

Asked, answered.

The questions evaluators actually ask, answered the way we answer them in a briefing.

01Questions

The short course.

What is breach intelligence?

Breach intelligence is knowledge of who is actually compromised, supported by evidence. It differs from threat intelligence, which describes adversaries and their tools in general, and from detection, which infers intrusions from signals inside your own environment. Vigilocity produces breach intelligence by monitoring adversary infrastructure at global scale and identifying the organizations in live communication with it.

What is Reverse Attack Surface Analysis (RASA)?

RASA is Vigilocity's methodology. It works from the attacker inward: tracking threat actors as they register domains, stand up command and control servers, and stage campaigns, then observing the victim networks that begin communicating with that infrastructure. The premise is a single question: if an adversary were going to attack us, what infrastructure would they need, where would it come from, and when would it appear?

What does "agentless" mean here?

Nothing is installed and no access to any environment is required. The observation happens on the adversary's side of the exchange, so Mythic needs no agents on endpoints, no appliances, no API credentials, and no participation from the organization being assessed.

How is this different from a security rating?

A security rating scores hygiene visible from the outside: open ports, patch cadence, certificate discipline. It describes the quality of the locks. Mythic observes whether anyone is currently inside the building: which networks are in live contact with adversary infrastructure, with timestamped evidence of the exchange. An organization can hold an excellent rating while actively breached; the two measurements are answering different questions.

How is this different from a threat intelligence feed?

A feed lists indicators, usually discovered after use and aggregated across sources. Mythic ties infrastructure to victims: it watches adversary infrastructure from the moment it is registered and identifies the organizations communicating with it, ranked by material impact. The output is not a list of bad domains. It is a statement about who is breached, with the evidence attached.

What evidence comes with a confirmed breach?

Each confirmed breach carries the date and time of the observed communication, the victim and destination IP addresses, the port and protocol, the data exfiltrated by the implant, the machine, user, operating system, and file paths involved, and the implant responsible.

Can Vigilocity assess an organization without its involvement?

Yes. Because assessment requires nothing from the subject, Mythic can evaluate third parties, vendors, acquisition targets, and insurance applicants from a distance, without questionnaires, deployed technology, or notification. This is the basis of the third-party risk, M&A due diligence, and cyber insurance solutions.

How does Mythic support SEC cyber disclosure?

Material cybersecurity incidents must be disclosed within four business days of a materiality determination. Mythic gives disclosure teams empirical evidence of what was reached, what was taken, and when, so the determination rests on observed fact rather than forensic estimates, and the clock is managed rather than feared.

How is Mythic priced?

As an annual subscription with two dimensions: the size of your organization, and how many other organizations you want in view, such as vendors, suppliers, or portfolio companies. There is no per-seat math and no tier that withholds capability. Pricing is discussed at a briefing.

What are the data feeds and API?

The same proprietary collection that powers Mythic, available as data: detailed malicious domain intelligence delivered as feeds, and a fully functional API for programmatic access to domain lookups, registrant pivots, IP threat resolution, DNS and data logs, and watchlists. The API is an OpenAPI 3 service documented at docs.vigilocity.com.

Which frameworks and regulations does Mythic map to?

Mythic's observations map to MITRE ATT&CK (reconnaissance, resource development, command and control, exfiltration), NIST CSF 2.0 (GOVERN, IDENTIFY, DETECT, RESPOND), ISO/IEC 27001:2022 threat intelligence and incident controls, and the evidence obligations in HIPAA, GDPR, NIS2, DORA, and NYDFS Part 500. Mappings are documented on the frameworks page; they are alignments, not certifications.

Who is behind Vigilocity?

Vigilocity was founded on two decades of counterintelligence operations inside adversary networks: infiltrating threat actor infrastructure, attributing state-sponsored campaigns, and watching attacks assemble from the inside. Clients include global financial institutions, Fortune 100 brands, Big Four advisory firms, and national governments, none of whom are named publicly.

02Glossary

Terms, precisely.

Breach intelligence
Evidence-backed knowledge of which organizations are compromised, produced by observation rather than inference.
RASA
Reverse Attack Surface Analysis: Vigilocity's methodology of tracking adversary infrastructure as it is built, then observing who communicates with it.
Mythic
Vigilocity's breach intelligence platform: continuous monitoring of adversary infrastructure, confirmed breaches with empirical evidence, materiality-ranked intelligence.
Adversary infrastructure
The domains, servers, and services a threat actor acquires to run campaigns: phishing sites, command and control, droppers, decoys, hop points.
Command and control (C2)
Infrastructure through which an attacker directs implants inside victim networks and receives stolen data.
Domain generation algorithm (DGA)
Software that mass-produces domain names on a template. Templated naming at registration is a strong signal of automated, malicious acquisition.
Dwell time
The interval between compromise and discovery. Traditionally months; observation from the adversary's side collapses it toward zero.
Materiality
The threshold at which an incident matters to a reasonable investor, triggering disclosure obligations. Mythic ranks confirmed breaches by material impact: what is being taken, and from whom.
Third-party risk (TPRM)
The discipline of managing risk from vendors and suppliers. Agentless observation lets a program watch the entire population continuously, without questionnaires.
Watchlist
In Mythic's API, a standing set of entities or network ranges under observation, with notifications when new matches appear.

A question this page doesn't answer?